Add zizmor (GitHub Actions security analysis) CI to a repository and fix every finding it surfaces. Use when asked to "add zizmor", harden a repo's GitHub Actions workflows, pin actions to SHAs, or make workflows pass a security audit. Adds a zizmor workflow + a dependabot config (on the default branch; other branches are covered via a dependabot `target-branch` entry there), then iterates locally until zizmor reports no findings, and opens a PR.
2026-05-29